An exploit kit hiding in the pixels of malicious ads
welivesecurity.com
welivesecurity.com
Neat, but not that impressive.
There have been so many vulnerabilities in Adobe Flash one has to wonder if they're deliberate. It's not a large body of code, after all.
Oh, of course it is. A complete scripting runtime engine (ActionScript), support for a boatload of video streaming formats including realtime communication, ...
Firefox clocks in at a healthy ~50 MB, as does Google Chrome, for the offline installers - Chrome expands to ~360MB app size, and Firefox to ~180MB (both current versions on OS X 10.11). I won't even get started on the RAM usage - a typical 10-tab session can easily munch happily through 4 GB RAM and more (especially when there are lots of ads).
It's a pity that a 3-year-old netbook (or cellphone) is basically unusable because browsers creep up so much in featuritis :(
Thank goodness that nightmare is over.
The Flash runtime is big, the API surface is huge and Adobe doesn't feel like it pours a lot of resources into maintenance today. The tech was nice but it should be banned from browsers today.
Obviously what I've just said doesn't help solve any problems here, but thought I'd throw it in there anyway :)
[1] https://docs.angularjs.org/api/ng/type/$rootScope.Scope#$eva...
You shouldn't need any kind of blocking for that, the browser should block it out of the box.
Seems like a single occurrence of "eval" should both fail that automatic review AND be blocked by default in all browsers using default security settings.
I think this just shows that ad networks shouldn't be using js at all. Just dumb images. (Yes I know, no tracking then which makes it useless yada yada - deal with it)
You're not wrong, but there are difficult customers with money to consider.
In google's case I can see the conflict - they both make a browser and live off ads. But apart from that minor issue I don't see why browser vendors don't just block "eval()"?
(Also, they have started blocking flash, thank god - so maybe this will all be a thing of the past soon)
My point is: online ads should become what bus stop ads have always been. You buy a space and display a dumb image. Did it work? You have to do your own A/B testing in half the city. What was it worth? You have to trust those you buy ad space from on how many people read their paper or pass by their bus stop.
Edit: Wikipedia article explains - you can call functions by name with that "filter" thing.
This should be pretty easily blockable though - if you block "eval" then just block most of the obscure jsfuck constructs too.
Edit: I also think ads are a bad source of income. It's based in psych warfare and in turn is based on toxic adversarial culture.
They are going to continue with both sponsored content AND ads. I'm just cutting off one side.
This nonsense, though? I don't remember the last time a classified ad leapt out of the newspaper and stole my grandmother's credit card.
Go on? That seems like it's blatantly and obviously false.
Even the publishers are being robbed blind.
There's really no one involved who isn't getting robbed at least some of the time.
Makes me wonder if there is a benefit in making a real machine appear to be a VM (or even if its possible).
If browsers restricted cross-origin sharing of image resources to same domain only, bazillions of dollars in tracking pixel revenue would evaporate.
Deep inspection of image rasters by script execution isn't going to get locked down anytime soon, I surmise.
Because I think that's the standard. If they can do it for Flash, then they can do it for anything else, too. They just need to set a deadline with a reasonable amount of time before it's reached so that all developers can adhere to the new specs.
I really hate the attitude of "well, too many websites/apps would be broken so I guess we'll never do it, or we'll just wait for the web to collapse first so that everyone agrees we should do it" from "platform" (in this case browser) vendors.
If it's that bad, then just set a 2 year, 3 year, or even 5 year deadline for the change (perhaps with some intermediary progressive blocking, like it's happening for Flash).
It pisses me off because it seems the same is happening with ASLR on Linux [1]. We've had it for 15 years, but nobody is willing to force developers to use it "because it would break things". Screw that. Set a deadline and do it already. If their apps can't make such a change in 3 years, then I could care less that their apps will stop working. Critical vulnerabilities that allow dangerous exploits to happen also "break a lot of things", and not just themselves either, but the firefighting patches that come after them, too.
I've been highly irritated by people freaking out that Flash is started to get blocked - despite it being deprecated in those browsers for years. It wasn't exactly a surprise.
But I guess that's the crap that hits us. No one will make a damned change till they're forced to do it right now.
I'm somewhat sick of advertising networks serving malware. JavaScript is Turing Complete, and leaky as hell. There is no safe way to use it for ads, so don't let you clients use it!
The modern web relying on huge megabytes worth of data has led to us needing CDNs and other 3rd party providers.
Anytime a websites uses a 3rd party provider, it opens a hole in itself, and with the insane complexity of a modern browser... That's just asking for trouble.
But asking Google to give up the practices they use to forward their own agendas, like advertising, and their walled garden of AMP, won't happen.
Chrome has the usage that it can exhibit considerable force on the other browsers, and the reverse isn't true.
EDIT: In other words, I completely agree with you, but cry when I see that state of things. Just want that to be clear.
However, I would quite like cross-origin blocking of things like flash and scripts. After all, that flash program that kicked the whole thing off probably wasn't loaded from the host web site. That seems much more sensible and low-impact to me. It also has a side-benefit of forcing ad networks to fall back to static images, which has to be a good thing.
wireshark as antivir ... nice to have ;)
Apple and Firefox (if Yahoo will let them) need to step up and block 3rd party scripts by default. Maybe even Chrome would get in on it if there was special whitelisting for Google's analytics.
All you'd need to do is serve up the same asset as any other site on the web and you could instantly know if the user has been there recently.
No need for tracking at all, just serve this up to people who go to HN, this to the redditors, this to anyone that was recently on 4chan...
Or let's take it a step further. I could reasonably figure out what your user-page on HN looks like to you when you're logged in. I'll serve that up to all my visitors and when I get a cache-hit I know it's you!
So this would work only on Internet Explorer?
Contact details in my bio.
Sounds better than an out of date AV solution!
(and cheaper)